CVE-2010-1163
published 2010-04-16CVE-2010-1163: The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a…
PriorityP424medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.40%
32.7th percentile
The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.7.2p6-1 (bookworm) | sudo 1.7.2p6-1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.7.2p6-1 | 1.7.2p6-1 |
| sudo_project | sudo | >= 0 < 1.7.2p6-1 | 1.7.2p6-1 |
| sudo_project | sudo | >= 0 < 1.7.2p6-1 | 1.7.2p6-1 |
| sudo_project | sudo | >= 0 < 1.7.2p6-1 | 1.7.2p6-1 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_cisco6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Sudo sudoedit Local Command Privilege Escalation Vulnerability
vendor_cisco·2010-04-19·CVSS 6.9
CVE-2010-1163 [MEDIUM] CWE-264 Sudo sudoedit Local Command Privilege Escalation Vulnerability
Sudo sudoedit Local Command Privilege Escalation Vulnerability
Sudo contains a vulnerability that could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges.
This vulnerability exists due to an error in the affected software while matching commands due to incorrect path resolution. A local attacker with privileges to run the sudoedit command could exploit this vulnerability to execute arbitrary commands with root privileges. An exploit could result in a complete system compromise.
Proof-of-concept code that exploits this vulnerability is publicly available.
The vendor has confirmed this vulnerability and released updated software.
To exploit the vulnerability, an attacker must have local access to the system and be granted special permissions to
Red Hat
sudo: incomplete fix for the sudoedit privilege escalation issue CVE-2010-0426
vendor_redhat·2010-04-13·CVSS 6.9
CVE-2010-1163 [MEDIUM] sudo: incomplete fix for the sudoedit privilege escalation issue CVE-2010-0426
sudo: incomplete fix for the sudoedit privilege escalation issue CVE-2010-0426
The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.
Package: sudo (Red Hat Enterprise Linux 4) - Not affected
Package: sudo (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-1163: sudo - The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not proper...
vendor_debian·2010·CVSS 6.9
CVE-2010-1163 [MEDIUM] CVE-2010-1163: sudo - The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not proper...
The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.
Scope: local
bookworm: resolved (fixed in 1.7.2p6-1)
bullseye: resolved (fixed in 1.7.2p6-1)
forky: resolved (fixed in 1.7.2p6-1)
sid: resolved (fixed in 1.7.2p6-1)
trixie: resolved (fixed in 1.7.2p6-1)
GHSA
GHSA-hh7m-2j26-qw2m: The command matching functionality in sudo 1
ghsa_unreviewed·2022-05-02·CVSS 6.9
CVE-2010-1163 [MEDIUM] CWE-20 GHSA-hh7m-2j26-qw2m: The command matching functionality in sudo 1
The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.
OSV
CVE-2010-1163: The command matching functionality in sudo 1
osv·2010-04-16·CVSS 6.9
CVE-2010-1163 [MEDIUM] CVE-2010-1163: The command matching functionality in sudo 1
The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.
Suricata
GPL NETBIOS RFParalyze Attempt
suricata·2010-09-23
CVE-2000-0347 GPL NETBIOS RFParalyze Attempt
GPL NETBIOS RFParalyze Attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS RFParalyze Attempt"; flow:established,to_server; content:"BEAVIS"; content:"yep yep"; reference:bugtraq,1163; reference:cve,2000-0347; reference:nessus,10392; classtype:attempted-recon; sid:2101239; rev:11; metadata:created_at 2010_09_23, cve CVE_2000_0347, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL NETBIOS NT NULL session
suricata·2010-09-23
CVE-2000-0347 GPL NETBIOS NT NULL session
GPL NETBIOS NT NULL session
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS NT NULL session"; flow:established,to_server; content:"|00 00 00 00|W|00|i|00|n|00|d|00|o|00|w|00|s|00| |00|N|00|T|00| |00|1|00|3|00|8|00|1"; reference:arachnids,204; reference:bugtraq,1163; reference:cve,2000-0347; classtype:attempted-recon; sid:2100530; rev:12; metadata:created_at 2010_09_23, cve CVE_2000_0347, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1163 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic SELECT
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic SELECT"; flow:established,to_server; http.uri; content:"/printview.php?"; nocase; content:"topic="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1163; reference:url,www.milw0rm.com/exploits/3351; classtype:web-application-attack; sid:2004748; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1163 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic INSERT
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic INSERT"; flow:established,to_server; http.uri; content:"/printview.php?"; nocase; content:"topic="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-1163; reference:url,www.milw0rm.com/exploits/3351; classtype:web-application-attack; sid:2004750; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-1163 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic ASCII
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic ASCII"; flow:established,to_server; http.uri; content:"/printview.php?"; nocase; content:"topic="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1163; reference:url,www.milw0rm.com/exploits/3351; classtype:web-application-attack; sid:2004752; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1163 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic UPDATE
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic UPDATE"; flow:established,to_server; http.uri; content:"/printview.php?"; nocase; content:"topic="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-1163; reference:url,www.milw0rm.com/exploits/3351; classtype:web-application-attack; sid:2004753; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1163 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic DELETE
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic DELETE"; flow:established,to_server; http.uri; content:"/printview.php?"; nocase; content:"topic="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1163; reference:url,www.milw0rm.com/exploits/3351; classtype:web-application-attack; sid:2004751; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1163 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic UNION SELECT
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic UNION SELECT"; flow:established,to_server; http.uri; content:"/printview.php?"; nocase; content:"topic="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1163; reference:url,www.milw0rm.com/exploits/3351; classtype:web-application-attack; sid:2004749; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, m
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039986.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/39384http://secunia.com/advisories/39399http://secunia.com/advisories/39474http://secunia.com/advisories/39543http://secunia.com/advisories/43068http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.577019http://wiki.rpath.com/Advisories:rPSA-2010-0075http://www.mandriva.com/security/advisories?name=MDVSA-2010:078http://www.osvdb.org/63878http://www.redhat.com/support/errata/RHSA-2010-0361.htmlhttp://www.securityfocus.com/archive/1/510827/100/0/threadedhttp://www.securityfocus.com/archive/1/510846/100/0/threadedhttp://www.securityfocus.com/archive/1/510880/100/0/threadedhttp://www.securityfocus.com/archive/1/514489/100/0/threadedhttp://www.securityfocus.com/bid/39468http://www.sudo.ws/sudo/alerts/sudoedit_escalate2.htmlhttp://www.ubuntu.com/usn/USN-928-1http://www.vupen.com/english/advisories/2010/0881http://www.vupen.com/english/advisories/2010/0895http://www.vupen.com/english/advisories/2010/0904http://www.vupen.com/english/advisories/2010/0949http://www.vupen.com/english/advisories/2010/0956http://www.vupen.com/english/advisories/2010/1019http://www.vupen.com/english/advisories/2011/0212https://exchange.xforce.ibmcloud.com/vulnerabilities/57836https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9382http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039986.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/39384http://secunia.com/advisories/39399http://secunia.com/advisories/39474http://secunia.com/advisories/39543http://secunia.com/advisories/43068http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.577019http://wiki.rpath.com/Advisories:rPSA-2010-0075http://www.mandriva.com/security/advisories?name=MDVSA-2010:078http://www.osvdb.org/63878http://www.redhat.com/support/errata/RHSA-2010-0361.htmlhttp://www.securityfocus.com/archive/1/510827/100/0/threadedhttp://www.securityfocus.com/archive/1/510846/100/0/threadedhttp://www.securityfocus.com/archive/1/510880/100/0/threadedhttp://www.securityfocus.com/archive/1/514489/100/0/threadedhttp://www.securityfocus.com/bid/39468http://www.sudo.ws/sudo/alerts/sudoedit_escalate2.htmlhttp://www.ubuntu.com/usn/USN-928-1http://www.vupen.com/english/advisories/2010/0881http://www.vupen.com/english/advisories/2010/0895http://www.vupen.com/english/advisories/2010/0904http://www.vupen.com/english/advisories/2010/0949http://www.vupen.com/english/advisories/2010/0956http://www.vupen.com/english/advisories/2010/1019http://www.vupen.com/english/advisories/2011/0212https://exchange.xforce.ibmcloud.com/vulnerabilities/57836https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9382
2010-04-16
Published